Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Tmerc Cogs MEDIUM 6.5
CVE-2021-37697

tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access…

Fix: 3.0+
Fix from $1,600 2021-08-11
Tmerc Cogs MEDIUM 6.5
CVE-2021-37696

tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access…

Fix: 3.0+
Fix from $1,600 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25563

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTask…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25566

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not requ…

No fix yet
Fix from $2,300 2021-08-11
Saml Single Sign On CRITICAL 9.8
CVE-2021-37843

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no othe…

Fix: 2.5.9 / 3.5.6+
Fix from $2,300 2021-08-02
Jira Data Center CRITICAL 9.8
CVE-2020-36239EPSS 47%

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.1…

Fix: 4.5.16 / 4.13.8+
Fix from $2,300 2021-07-29
Archisteamfarm HIGH 7.5
CVE-2021-32794

ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /…

Fix: 5.1.2.4+
Fix from $1,950 2021-07-26
Syracuse HIGH 7.2
CVE-2020-7389

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by t…

Fix: 9.22.7.2 / 11.25.2.6+
Fix from $1,950 2021-07-22
T200i Firmware CRITICAL 9.8
CVE-2021-22772

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 …

Mitigation only
Fix from $2,300 2021-07-21
C Bus Toolkit MEDIUM 5.7
CVE-2021-22784EPSS 12%

A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a…

Fix: 1.15.9+
Fix from $1,600 2021-07-21
Cx2 Firmware HIGH 7.5
CVE-2020-21934

An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.

No fix yet
Fix from $1,950 2021-07-21
Cx2 Firmware MEDIUM 5.3
CVE-2020-21936

An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSett…

No fix yet
Fix from $1,600 2021-07-21
Sharecare CRITICAL 9.8
CVE-2021-36124

An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive res…

Mitigation only
Fix from $2,300 2021-07-13
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28809EPSS 16%

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack…

Fix: 3.0.210506 / 3.0.210507+
Fix from $2,300 2021-07-08
Guardium Data Encryption HIGH 7.5
CVE-2021-20474

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o…

Patch available
Fix from $1,950 2021-07-07
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33221EPSS 56%

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Profilepress CRITICAL 9.8
CVE-2021-34621EPSS 69%

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it …

Fix: after 3.1.3
Fix from $2,300 2021-07-07
Optima Eaf 100 Firmware MEDIUM 5.4
CVE-2021-20107

There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS…

No fix yet
Fix from $1,600 2021-06-30
Wd My Book Live Firmware HIGH 7.5
CVE-2021-35941EPSS 13%

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory re…

No fix yet
Fix from $1,950 2021-06-29
Sinamics Sl150 Firmware CRITICAL 9.8
CVE-2021-31337

The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote …

Mitigation only
Fix from $2,300 2021-06-28
Dsl 2888a Firmware CRITICAL 9.8
CVE-2021-33346

There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the …

No fix yet
Fix from $2,300 2021-06-24
Ballerina HIGH 7.4
CVE-2021-32700

Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha…

Fix: 1.2.14+
Fix from $1,950 2021-06-22
White Shark Systems MEDIUM 5.3
CVE-2020-20472

White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication oper…

No fix yet
Fix from $1,600 2021-06-21
Iview CRITICAL 9.8
CVE-2021-32930EPSS 8%

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar…

Fix: 5.7.03.6182+
Fix from $2,300 2021-06-11
Cpp6 Firmware CRITICAL 9.1
CVE-2021-23847

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang…

Fix: 7.80.0129+
Fix from $2,300 2021-06-09
Bird MEDIUM 6.8
CVE-2021-26928

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for e…

Fix: after 2.0.7
Fix from $1,600 2021-06-04
Emui MEDIUM 6.8
CVE-2021-22316

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby …

Mitigation only
Fix from $1,600 2021-06-03
Emui HIGH 7.5
CVE-2021-22322

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair …

Mitigation only
Fix from $1,950 2021-06-03
3scale MEDIUM 5.4
CVE-2020-25634

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…

Fix: 2.10.0+
Fix from $1,600 2021-05-26
Vcenter Server CRITICAL 9.8
CVE-2021-21986EPSS 13%

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26